Staying Sneaky in the Office 365 - Exploiting Hidden SharePoint APIs for Azure Lateral Movement
fwd:cloudsec via YouTube
AI, Data Science & Cloud Certificates from Google, IBM & Meta
Learn Backend Development Part-Time, Online
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
Explore advanced Microsoft SharePoint Online security vulnerabilities and attack techniques in this 25-minute conference talk that delves into lesser-known APIs and their exploitation potential. Learn how attackers can leverage SharePoint's internal APIs to bypass Microsoft Graph detection methods and evade modern security controls within Azure environments. Discover enumeration techniques that allow lateral movement throughout Office 365 tenants, understand the differences between SharePoint Online internals and Microsoft Graph APIs, and examine how regular business users with SharePoint access can potentially compromise sensitive organizational resources. Gain insights into file sharing security control bypasses and acquire practical defensive strategies for preventing and detecting direct API usage attempts, equipping security teams with knowledge to better protect their cloud environments against sophisticated adversaries targeting interconnected Microsoft services.
Syllabus
Staying Sneaky in the Office (365)
Taught by
fwd:cloudsec